Back to the hub

What are the penalties under the Oregon Consumer Privacy Act?

Oregon's privacy law carries a civil penalty of up to $7,500 for each violation, enforced only by the Oregon Attorney General. Since January 1, 2026, there is no right to cure: the 30-day notice provision was removed, so the attorney general can sue without warning.

Applies to: Controllers and processors subject to the Oregon Consumer Privacy Act, particularly those relying on an opportunity to fix a violation after receiving notice from the Oregon Department of Justice.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Most summaries of Oregon's privacy law still describe a 30-day right to cure. They are describing a rule that expired. On January 1, 2026 the cure provision came out of the statute, and Oregon joined Colorado as a state where the attorney general does not have to warn you first.

The number: $7,500 per violation

The Act authorizes the Attorney General to bring an action to impose a civil penalty of not more than $7,500 for each violation, or to enjoin a violation or obtain other equitable relief. The Oregon Department of Justice repeats the figure in its enforcement FAQs and adds that the Attorney General can also seek injunctive relief, restitution, and disgorgement.

"Each violation" is the phrase to sit with. A single misconfigured tag that shares data about a large number of Oregon consumers is not obviously one violation, and the statute does not do the arithmetic for you.

The cure period was designed to expire

This is the part that catches people, and it is worth being precise about, because the trap is that the expiry was written into the original law rather than added by a later amendment.

SB 619 contained the enforcement section, and it also contained a second, amended version of that same section. The amended version drops the subsection that required the Attorney General to give a controller written notice and 30 days to cure. The Act then sets the switchover date: the amendments to section 9 by section 11 of the 2023 Act become operative on January 1, 2026.

So the cure right existed for the first 18 months of the law and then stopped. The Oregon Department of Justice says the same thing in its own words: as of January 1, 2026 the Attorney General is no longer required to give controllers notice and an opportunity to cure regardless of the nature of the violation, and can proceed directly to an enforcement action such as serving a civil investigative demand or filing a lawsuit.

If a page you are reading says Oregon gives you 30 days to fix a problem, check its date.

Who can enforce, and who cannot

The Attorney General has sole enforcement power. There is no private right of action, so a consumer cannot bring a claim under this statute. Actions are brought in the circuit court for Multnomah County.

That concentrates the risk in one place, which cuts both ways. There is no plaintiff's bar to worry about, but there is also no volume of small claims to absorb attention. When Oregon acts, it is the state acting.

Two obligations that arrived with the same deadline

January 1, 2026 was a busy date for Oregon. Alongside the loss of the cure right, HB 2008 took effect, and it made two things unlawful that were previously allowed: selling personal data that identifies a consumer's past or present location within a radius of 1,750 feet, for consumers of any age, and selling the personal data of a consumer the controller knows or willfully disregards is under 16. The duty to honor a universal opt-out mechanism also became mandatory on that date.

A business that reviewed its Oregon posture in 2025 and has not looked since is out of date on all three points, and no longer has a cure period to absorb the difference.

Next step

The gap between what most Oregon guidance says and what the statute now says is exactly the kind of thing that turns into a penalty. The free 2-minute Obligation Scan checks your business against every US state privacy law and GDPR and shows which obligations apply to you right now. See the Oregon Consumer Privacy Act overview for the applicability thresholds, Oregon response deadlines for the request and appeal clocks, and Colorado fines and penalties for the other state that removed its cure right. Plans and pricing are on the pricing page.

Compliance checklist

  • Stop planning around a cure period. Oregon removed it on January 1, 2026, so the first contact from the Department of Justice may be an investigative demand rather than a warning letter.
  • Count exposure per violation, not per incident, because the $7,500 cap attaches to each violation of the Act.
  • Budget for more than the penalty. The Attorney General can also seek injunctive relief, restitution, and disgorgement on top of civil penalties.
  • Have a documented response process for an Oregon investigative demand, including who is authorized to respond and where the underlying records live.
  • Re-check the two obligations that changed on January 1, 2026: the ban on selling precise geolocation data and the duty to honor a universal opt-out mechanism.

Sources

Last verified: 2026-09-01

Informational, not legal advice.